CWE-680: Integer Overflow to Buffer Overflow
The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.
104 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-53630 — Integer Overflow in GGUF Parser can lead to Heap Out-of-Bounds Read/Write in gguf
- CVE-2025-53510 — A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9
- CVE-2025-52930 — A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9
- CVE-2025-52456 — A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.
- CVE-2025-46407 — A memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library
- CVE-2025-32468 — A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0
- CVE-2025-20263 — Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Buffer Overflow Denial of Service Vulnerability
- CVE-2024-48877 — A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility vers
- CVE-2024-37305 — Buffer overflow in deserialization in oqs-provider
- CVE-2025-21442 — Integer Overflow to Buffer Overflow in Automotive Vehicle Networks
- CVE-2024-38422 — Integer Overflow to Buffer Overflow in Audio
- CVE-2026-19313 — Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution
- CVE-2026-55200 — libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
- CVE-2025-23326 — NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer o
- CVE-2024-58107 — Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail
- CVE-2024-56451 — Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this
- CVE-2026-43627 — llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function
- CVE-2025-32023 — Redis allows out of bounds writes in hyperloglog commands leading to RCE
- CVE-2025-54623 — Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may
- CVE-2026-8376 — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
Recently published
- CVE-2026-81647 — Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec
- CVE-2026-19313 — Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution
- CVE-2026-70651 — libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick
- CVE-2026-19588 — Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
- CVE-2026-43627 — llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function
- CVE-2026-55200 — libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
- CVE-2026-8376 — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
- CVE-2026-24928 — Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may a
- CVE-2026-25541 — Bytes is vulnerable to integer overflow in BytesMut::reserve
- CVE-2025-46407 — A memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library
- CVE-2025-32468 — A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0
- CVE-2025-53510 — A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9
- CVE-2025-52930 — A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9
- CVE-2025-52456 — A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.
- CVE-2025-20263 — Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Buffer Overflow Denial of Service Vulnerability
- CVE-2025-23326 — NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer o
- CVE-2025-54623 — Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may
- CVE-2025-53630 — Integer Overflow in GGUF Parser can lead to Heap Out-of-Bounds Read/Write in gguf
- CVE-2025-32023 — Redis allows out of bounds writes in hyperloglog commands leading to RCE
- CVE-2024-48877 — A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility vers